Data Protection at Prime Auto
Introduction
At Prime Auto, located in Gibraltar, we are committed to protecting your privacy and ensuring the security of your personal data. This Data Protection page outlines how we collect, use, store, and process your personal information in accordance with the Gibraltar General Data Protection Regulation (GDPR) and the Data Protection Act 2004.
Who We Are (Controller)
Prime Auto Ltd – Reg. no 107074
📍 Rodgers Road – Gibraltar
📞 +350 20066634 or +350 56000341
✉️ marianieto@primeauto.gi
We are the data controller responsible for the processing of your personal data in connection with our website and services.
What Personal Data We Collect
We may collect and process the following types of personal data:
Contact Information: Name, address, email address, phone number.
Vehicle Information: Vehicle make, model, registration number, and service history.
Financial Information: Payment details, credit information (if applicable for financing).
Website Usage Data: IP address, browser type, operating system, pages visited, browsing activity (collected through cookies and similar technologies—please see our Cookie Policy).
Marketing Preferences: Whether you have consented to receive marketing communications from us.
Enquiry Data: Information provided when you contact us with inquiries about our vehicles or services.
Sales and Service Data: Records of vehicles purchased, services carried out, and related communications.¡
How We Use Your Personal Data (Purposes of Processing)
We may process your personal data for the following purposes:
To respond to your inquiries and provide information about our vehicles and services.
To process your vehicle purchase or service requests.
To manage and administer your account with us.
To provide after-sales service and support.
To process financing applications (where applicable).
To send you marketing communications (where you have provided consent).
To improve our website and services (through analysis of usage data).
To comply with legal and regulatory obligations.
For internal record-keeping and administrative purposes.
Legal Basis for Processing
Our legal basis for processing your personal data may include:
Consent: Where you have freely given your specific, informed, and unambiguous consent for a particular purpose (e.g., marketing). You have the right to withdraw your consent at any time.
Contract: Where processing is necessary for the performance of a contract with you (e.g., processing your vehicle purchase or service).
Legal Obligation: Where processing is necessary for compliance with a legal obligation to which we are subject.
Legitimate Interests: Where processing is necessary for our legitimate interests or the legitimate interests of a third party, provided that your interests and fundamental rights do not override those interests (e.g., improving our services, direct marketing where a legitimate interest exists under the law).
Who We Share Your Personal Data With (Recipients)
We may share your personal data with the following categories of recipients:
AMC Credit: For processing financing applications (if you choose this option). Their data protection policy will also apply to their processing.
Vehicle Manufacturers (Hyundai, Citroën, Silence, Piaggio Commercial): For warranty purposes, service updates, and other legitimate reasons related to your vehicle.
Service Providers: Third-party companies that provide services on our behalf, such as IT support, website hosting, marketing services, and payment processing. We ensure these providers have appropriate data protection safeguards in place.
Legal Authorities: When required by law or to comply with a legal process.
International Transfers of Personal Data
Suppose we transfer your personal data to countries outside of Gibraltar and the European Economic Area (EEA). In that case, we will ensure that appropriate safeguards are in place to protect your data following the GDPR, such as using Standard Contractual Clauses approved by the European Commission.
How Long We Keep Your Personal Data (Retention Period)
We will retain your personal data for as long as necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements. The retention period will depend on the specific type of data and the purpose of processing. For example, we will typically retain customer purchase and service records for a period required by law for warranty and accounting purposes. Marketing data will be retained until you withdraw your consent.
Your Rights Under the GDPR and Data Protection Act 2004
You have several rights regarding your personal data, including:
The right to access: You can request a copy of the personal data we hold about you.
The right to rectification: You can ask us to correct any inaccurate or incomplete personal data.
The right to erasure (‘right to be forgotten’): You can ask us to delete your personal data in certain circumstances.
The right to restriction of processing: You can ask us to restrict the processing of your personal data in certain circumstances.
The right to data portability: You can request to receive your personal data in a structured, commonly used, and machine-readable format and to transmit it to another controller.
The right to object: You can object to the processing of your personal data in certain circumstances, including for direct marketing purposes.
Rights in relation to automated decision-making and profiling: You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you, unless there is a lawful basis for such processing.
The right to withdraw consent: If we are processing your personal data based on your consent, you have the right to withdraw that consent at any time.
The right to lodge a complaint: You have the right to lodge a complaint with the Gibraltar Regulatory Authority (GRA) if you believe that our processing of your personal data infringes the GDPR or the Data Protection Act 2004.
How to Exercise Your Rights
If you wish to exercise any of your rights, please use the contact details provided at the beginning of this Data Protection page. We will respond to your request without undue delay and in accordance with applicable data protection laws. We may need to verify your identity before processing your request.
Our website uses cookies and similar technologies to collect information about your browsing activity. Please refer to our separate Cookie Policy for detailed information about the cookies we use and how you can manage your cookie preferences.
We may update this Data Protection page from time to time to reflect changes in our data processing practices or legal requirements. We will post any changes on our website, and we encourage you to review this page periodically. The date of the last update will be indicated below.